SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-1497

Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

KEVCRITICAL 9.8EPSS 99.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 November 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.93% probability · 100th percentile
CISA KEV
Listed 3 November 2021 · due 17 November 2021
Weakness
CWE-78
Affected
cisco/hyperflex hx data platform
Source
psirt@cisco.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-1497

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.